with-cte@1.0.0
Malicious code in with-cte (npm)
Analysis
with-cte@1.0.0 ships a preinstall hook (`node index.js`) that executes automatically on `npm install`. The script performs host reconnaissance — it collects the package name and version, the install directory, the home directory, the hostname, the current username, the configured DNS resolvers and the full package.json — and additionally reads /etc/passwd and /etc/hosts. It then POSTs all of this as a JSON body over HTTPS to the Burp Collaborator collection endpoint 187d714jo62z5j5c39hc437myd44sxgm[.]oastify[.]com on port 443 at path /. The package contains no other functionality: its sole purpose is install-time exfiltration of host and account data to an attacker-controlled collector.
- analyzed by
- Leitwacht
- first seen
- Oct 5, 2026, 08:04 AM
- analyzed
- Oct 5, 2026, 09:59 AM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.